Cybersecurity · Thursday, 20 August 2026
01 · Briefing · what happened
The attacker nobody wrote down already had a valid login
Records from the US border agency, a Somerset hospital and a camera network all show the same gap: systems built to keep strangers out, broken by people who were let in.
~300
alleged database-misuse cases
US border staff, 2009 to 2022
95%
were hit through a different tool
of 2,500 orgs blamed on a poisoned AI package
3.7m
people in one health-records breach
from eight hours of access at CareCloud
1.7bn
logins stolen in six months
by password-stealing malware, per Flashpoint
At a glance
- WIRED published records showing close to 300 alleged cases, from 2009 to 2022, of US border staff using government databases to look up romantic interests, family and colleagues.
- A Somerset hospital worker opened up to 200 patient records over six years and sent one as a screenshot to her partner. She got a police caution.
- Flock's chief executive conceded it took too long to stop police stalking exes with its cameras. Its abuse-flagging feature was optional and only about a third of forces used it.
- WIRED then rebuilt Flock's unreleased police AI from files the company's own site was serving, and found it identifies drivers by movement patterns alone.
- Researchers say 95% of the 2,500 organisations blamed on a poisoned AI package were already compromised days earlier through a different tool, Trivy.
- The outsider threats everyone plans for moved fast: a GeoServer flaw drew hundreds of attacks within hours of a researcher posting it, still with no patch.
- A face-search site promising privacy left 9 million photos in an open store, and a crypto-wallet maker guarded the keys while leaking its customer list.
Forces in play
Close to 300 alleged cases at the US border agency, a six-year run of snooping at a Somerset hospital, and 50-plus police accused of abusing Flock cameras. All had valid logins.
A GeoServer flaw drew hundreds of attacks within hours of a researcher posting it, and VMware vCenter fell five days after the fix was announced.
Researchers now blame the Trivy scanner, not LiteLLM, for 95% of a 2,500-organisation compromise. Firms had named the wrong entry point for months.
Flock has made its abuse-flagging compulsory and cut default retention from 30 days to seven, and Premier League clubs now face 100,000-pound fines for failing security rules.
How it unfolded
- 12 Aug A GeoServer flaw is posted publicly and attacked within hours
- 13 Aug WIRED publishes the border-agency records; Flock announces guardrails
- 14 Aug Researchers say Trivy, not LiteLLM, was the real entry point
- 18 Aug CISA adds four already-exploited flaws to its catalogue
- 19 Aug The Somerset hospital case and Flock's unreleased AI tool are both reported
Where this points
Watch whether Flock's now-compulsory abuse flagging produces cases that reach a courtroom, because the pattern so far is resignation and a caution rather than a prosecution.
Full briefing
The week the insider showed up in three countries at once
WIRED published internal records this week showing how staff at US Customs and Border Protection allegedly used government databases for reasons that had nothing to do with the job
The allegations are mundane and specific. One officer is accused of pulling contact details from trusted-traveller applications to ask people out
Two days ago the BBC reported the British version. A worker at Musgrove Park Hospital in Somerset looked at up to 200 patient records over six years, from August 2017 to October 2023
And Flock Safety’s chief executive, Garrett Langley, was asked by the BBC whether his firm had taken too long to stop police misusing its camera network. He answered: “Yeah… yes”
The same company’s next tool goes further than it said it could
Flock has told the public for years that its cameras “cannot recognize, identify, or track individuals”
It ships with 69 prewritten prompts and has 45 tools at its disposal
Two firms that guarded the wrong thing
A face-search site called ClarityCheck tells users their reverse image search is “private and secure.” Researcher Jeremiah Fowler found it had left roughly 450 GB and more than 9 million image files in an unsecured Amazon storage bucket
SafePal, which makes hardware wallets for cryptocurrency, disclosed an authorisation flaw in an order-tracking plug-in. It exposed the names, email addresses, shipping addresses and phone numbers of about 39,798 customers
The correction: 2,500 organisations blamed the wrong door
Earlier reporting attributed a large software supply-chain compromise to two poisoned versions of LiteLLM, an AI tool, that sat online for roughly 40 minutes in March. SOCRadar’s analysis of per-organisation records says otherwise
The real entry point was upstream: a compromise of Aqua Security’s Trivy scanner, which spread downstream through automated builds
The threats everyone did write down moved very fast
A new SQL injection flaw in GeoServer, open-source mapping software, was disclosed by a researcher on X at 10:46 UTC on 12 August
CISA, the US cyber-defence agency, added four already-exploited flaws to its catalogue in a single day on 18 August
The vCenter flaw, CVE-2026-59310, was exploited within five days of Broadcom’s advisory
The volume underneath
Health software firm CareCloud told US regulators that 3,756,469 people were affected
RingCentral, used by more than 600,000 businesses, had personal data on 1.6 million accounts taken by the ShinyHunters extortion group after a July intrusion
Latvia’s road traffic agency confirmed hackers took payment-receipt data going back to 2008 on more than 1.2 million people and 200,000 businesses
A seller calling themselves TheHatman claims to have taken millions of employee records from the Microsoft cloud tenants of nine large organisations
And the list of who might come for you is being rewritten
The extortion group Clop is still working through victims of a flaw in PTC’s Windchill and FlexPLM software, which manufacturers use to run supply chains
A presidential memorandum released late on 12 August allows vetted US companies to run offensive operations against foreign cybercrime groups, partnering with the Justice and Homeland Security departments
Premier League clubs now face fines of up to 100,000 pounds ($135,280) for failing to meet mandatory cybersecurity rules introduced this season
02 · Lesson · why it matters
Safe from whom? The question that has to come first
Nothing is secure in the abstract. A thing is only secure against a particular someone, trying a particular thing, for a particular reason.
How it works
- Name what you are protecting
- Name who would want it
- Name what they could do
- Name what happens if they succeed
- Whatever is left off that list is still a decision
The twist
The real output of a threat model is the list of attackers you have decided not to stop. You produce that list whether or not you write it down.
Where you've seen this
Home insurance
the policy is a written list of what you are not covered for
Airport screening
everything checked is chosen, so everything else is chosen too
A shop till
the camera faces the customers, not the person holding the keys
A school gate
locked against strangers, open to everyone with a lanyard
The catch
The attacker gets to read your model and move, so a good one goes stale and has to be revisited rather than framed.
Full lesson
A lock is not good or bad on its own
Ask whether a bike lock is any good and there is no answer yet. A cable lock defeats a bored teenager with bolt cutters. It does not defeat a van, an angle grinder and twenty unwatched minutes. The lock has not changed between those two sentences. What changed is who you had in mind.
That is the whole of it. “Secure” is an unfinished sentence. It only means something once you say secure against whom, doing what, and how much it costs you if they win.
The four questions, in order
The discipline that finishes the sentence is called threat modelling, and it is four plain questions.
What am I protecting? Who would want it? What could they do? What happens if they succeed?
They have to run in that order. Answer the first and the second becomes obvious in a way it never is when you start from the technology. A hospital protects patient records. Who wants a patient record? Not only a foreign intelligence service. Also a colleague who is curious whether someone is pregnant.
The output is the list you leave off
Here is the part people miss. A threat model does not really produce a list of attackers you will stop. It produces the list you will not.
You have a budget, so some names come off. That is fine and unavoidable. What matters is whether the removal is a decision or an accident. The Somerset hospital had an audit trail good enough to reconstruct six years of snooping after the fact. What it did not have was anyone treating its own staff as a party worth watching in advance.
The border agency’s databases have classification, access control and an office of professional responsibility. Close to three hundred alleged cases still ran through them across thirteen years. The camera company built a feature that flags odd searches, then made it optional, and about a third of forces turned it on. Every one of those is a decision about who not to defend against. None of them looks like a decision at the time.
Not the same as the other three
Two neighbouring ideas are worth separating out, because they sound close and are not.
One says a system must stay safe even when its design is fully public, and the only real secret is the key. That is about what may be known. This is a step earlier: secret from whom, and worth what to them.
The other is about cost. Make an attack expensive enough and it stops paying. True, but it presumes you already know which attacker you are pricing against. A wall priced for a criminal is not priced for a colleague, because the colleague is not paying to get in. They already have the key.
What being wrong looks like
Threat models fail in two shapes, and both showed up this week.
The first is naming the wrong door. Thousands of organisations spent months believing they had been reached through one poisoned package that was online for forty minutes. The analysis now says most were already exposed days earlier through a different tool upstream. Everyone had a model. It pointed at the wrong entry.
The second is guarding exactly the right thing and nothing beside it. A hardware wallet maker protected keys and seed phrases perfectly, and leaked a list of names, phone numbers and home addresses of people known to own crypto. The keys were the asset. The list of owners turned out to be one too.
Who is inside this
None of this stays in the server room. If the answer to “who would want it” gets drawn narrowly, the people outside that line are ordinary. A patient in Somerset. A driver in a town that bought cameras. Someone who applied for a trusted-traveller card in 2011. They were never party to the modelling. They only appear in it as data.
And the model itself is a guess about someone who gets to read it and move. Publish the guardrails and the pressure shifts to whatever the guardrails do not cover. So a threat model is not a document you finish. It is a thing that quietly goes out of date while you are still proud of it, and you notice mostly by being wrong in a new way.
That is the honest position. Everyone is working from a list of people they decided not to worry about, and none of us can see the whole of our own list.
03 · Lab · your turn
Name Your Attacker
Choose which attackers you will defend against and see that the ones you leave off the list are a decision you made.
04 · Hope · carry this
Every one of those cases surfaced because someone kept a record or filed a request. The list of people we forget to watch keeps getting shorter, one uncomfortable disclosure at a time.
More from Cybersecurity